CVE-2015-0734: XSS
Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Email Security Appliance (ESA) 8.5.6-106 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug ID CSCut87743.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0734?
CVE-2015-0734 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-0734?
To mitigate CVE-2015-0734, update your Cisco Email Security Appliance firmware to version 8.5.6-107 or later.
What types of attacks can CVE-2015-0734 enable?
CVE-2015-0734 can enable remote attackers to perform cross-site scripting (XSS) attacks.
Which versions are affected by CVE-2015-0734?
CVE-2015-0734 affects Cisco Email Security Appliance firmware version 8.5.6-106.
Can CVE-2015-0734 be exploited without authentication?
Yes, CVE-2015-0734 can be exploited by unauthenticated remote attackers through specially crafted requests.